Microsoft Designing and Implementing Microsoft Azure Networking Solutions - AZ-700 Exam Practice Test

Hotspot Question
You have an on-premises web server that hosts a web app named App1 and has the following configurations:
- IP address: 131.107.50.60
- FQDN: server1.contoso.com
You have an Azure subscription.
You need to publish App1 by using Azure Front Door. The solution must meet the following requirements:
- Ensure that internet users can connect to App1 by using an FQDN of
app1.contoso.com.
- Minimize the changes required to the configuration of Front Door if
Server1 is migrated to Azure.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
SIMULATION

Username and password
Use the following login credentials as needed:
- To enter your username, place your cursor in the Sign in box and click on the username below.
- To enter your password, place your cursor in the Enter password box and click on the password below.
- Azure Username: [email protected]
- Azure Password: xxxxxxxxxx
If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
- Lab Instance: 12345678
You plan to use VNET4 for an Azure API Management implementation.
You need to configure a policy that can be used by an Azure application gateway to protect against known web attack vectors. The policy must only allow requests that originate from IP addresses in Canada. You do NOT need to create the application gateway to complete this task.
To complete this task, sign in to the Azure portal.
Correct Answer:
Hotspot Question
You have two on-premises sites named Site1 and Site2. Each site connects to the internet by using a local firewall device.
You have an Azure subscription that contains two virtual networks named VNet1 and VNet2.
VNet1 and VNet2 reside in the East US Azure region and are connected by using virtual network peering.
You need to configure a Site-to-Site (S2S) VPN solution that meets the following requirements:
- Site1 and Site2 must connect directly to the Azure subscription by
using their local firewall device.
- The computers in Site1 and Site2 must be able to connect to the
resources on VNet1 and VNet2.
- The solution must include a virtual network gateway that uses three
availability zones.
What is the minimum number of virtual network gateways and local network gateways that you should deploy to Azure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
You have an Azure virtual network named VNet1 that contains the subnets shown in the following table.

You need to deploy an Azure application gateway named AppGW1 to VNet1.
To where can you deploy AppGW1?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Hotspot Question
You have an on-premises VPN appliance named GW1.
You have an Azure subscription that contains an Azure VPN gateway named VPNGW1.
VPNGW1 connects to GW1.
You need to modify the IKEv2 encryption algorithm used by VPNGW1 and GW1.
Which PowerShell cmdlet should you run? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:
SIMULATION

Username and password
Use the following login credentials as needed:
- To enter your username, place your cursor in the Sign in box and click on the username below.
- To enter your password, place your cursor in the Enter password box and click on the password below.
- Azure Username: [email protected]
- Azure Password: xxxxxxxxxx
- If the Azure portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
- Lab Instance: 12345678
You need to ensure that subnet 4-3 can accommodate 507 hosts.
To complete this task, sign in to the Azure portal.
Correct Answer:
Hotspot Question
You have an on-premises server named Server that is assigned a public IP address of
131.107.100.200.
You have an Azure subscription that contains the resources shown in the following table.

storage85347 has the Networking settings configured as shown in the following exhibit.

From the Firewalls and virtual networks tab, you add Subnet1 to storage85347.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Correct Answer:
Drag and Drop Question
Your on-premises network uses an IP address space of 10.0.0.0/20.
You have an Azure subscription that contains the resources shown in the following table.

The on-premises network is connected to HubVnet by using a Site-to-Site (S2S) VPN.
You deploy an Azure firewall named AZFW1 to HubVNet.
You need to ensure that AZFW/1 can inspect all the traffic between the on-premises network and SpokeVNet.
What should you do in RT1? To answer, drag the appropriate destination to the correct route.
Each resource may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Correct Answer:
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure subscription that contains an Azure Virtual WAN named VWAN1. VWAN1 contains a hub named Hub1.
Hub1 has a security status of Unsecured.
You need to ensure that the security status of Hub1 is marked as Secured.
Solution: You implement Azure NAT Gateway.
Does this meet the requirement?
Correct Answer: A
You have an instance of Azure Web Application Firewall (WAF) on Azure Front Door.
You plan to create a WAF rule that will block high rates of requests from a single IP address.
You need to query Log Analytics to identify the optimal threshold for the rule.
Which table should you query in Log Analytics?
Correct Answer: A
You have an Azure subscription that contains the following resources:
- A virtual network named Vnet1
- Two subnets named subnet1 and AzureFirewallSubnet
- A public Azure Firewall named FW1
- A route table named RT1 that is associated to Subnet1
- A rule routing of 0.0.0.0/0 to FW1 in RT1
After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual machines were activated.
You need to ensure that the virtual machines can be activated.
What should you do?
Correct Answer: D
You have the Azure resources shown in the following table.

You configure storage1 to provide access to the subnet in Vnet1 by using a service endpoint.
You need to ensure that you can use the service endpoint to connect to the read-only endpoint of storage1 in the paired Azure region.
What should you do first?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Hotspot Question
You have an Azure subscription that contains the resources shown in the following table.

You plan to deploy an app named App1 to meet the following requirements:
- External users must be able to access App1 from the internet.
- App1 will be load balanced across all the virtual machines.
- App1 will be hosted on VM1, VM2, VM3, and VM4.
- App1 must be available if an Azure region fails.
- Costs must be minimized.
You need to implement a global load balancer solution for App1.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct answer is worth one point.
Correct Answer:
Hotspot Question
Your company has 10 instances of a web service. Each instance is hosted in a different Azure region and is accessible through a public endpoint.
The development department at the company is creating an application named App1. Every 10 minutes. App1 will use a list of end points and connect to the first available endpoint.
You plan to use Azure Traffic Manager to maintain the list of endpoints.
You need to configure a Traffic Manager profile that will minimize the impact of DNS caching.
What should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Correct Answer:

Explanation:
A traffic manager Multivalue profile can have only endpoints of type "External" Multivalue traffic-routing method The Multivalue traffic-routing method allows you to get multiple healthy endpoints in a single DNS query response. This configuration enables the caller to do client-side retries with other endpoints in case a returned endpoint being unresponsive. This pattern can increase the availability of a service and reduce the latency associated with a new DNS query to obtain a healthy endpoint.
MultiValue routing method works only if all the endpoints of type 'External' and are specified as IPv4 or IPv6 addresses. When a query is received for this profile, all healthy endpoints are returned and are subject to a configurable maximum return count.
https://docs.microsoft.com/en-us/azure/traffic-manager/traffic-manager-routing-methods#multivalue
0
0
0
0